PT-2014-5935 · Sgminer+2 · Sgminer+2
Mick Ayzenberg
·
Publicado
2014-07-23
·
Atualizado
2015-08-28
·
CVE-2014-4502
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
sgminer versions prior to 4.2.2
cgminer versions prior to 4.3.5
BFGMiner versions prior to 4.1.0
Description
The issue is related to multiple heap-based buffer overflows in the
parse notify function. This can be triggered by remote pool servers sending a mining.subscribe response with a large or negative value in the Extranonc2 size parameter, followed by a crafted mining.notify request. The impact of this issue is unspecified.Recommendations
For sgminer versions prior to 4.2.2, update to version 4.2.2 or later.
For cgminer versions prior to 4.3.5, update to version 4.3.5 or later.
For BFGMiner versions prior to 4.1.0, update to version 4.1.0 or later.
Exploit
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Bfgminer
Cgminer
Sgminer